Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
219 results
aisecplus-week01-servicenow-ai-security-incident preview

aisecplus-week01-servicenow-ai-security-incident

GitHubololadeabiola03/aisecplus-week01-servicenow-ai-security-incident

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

ai-securityauthentication-authorizationcloud-security+5
2 months ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
1 month ago
CVE-2026-33186 preview

CVE-2026-33186

GitHubjohanneslks/cve-2026-33186

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

api-securityauthentication-authorizationeducation+3
12 months ago
CVE-2026-39275 preview

CVE-2026-39275

GitHubsecurify-ai/cve-2026-39275

CVE-2026-39275 - Stored XSS Leading to Account Takeover in Cockpit CMS

educationexploitationpenetration-testing+3
12 months ago
CVE-2022-21449-vuln-test preview

CVE-2022-21449-vuln-test

GitHubjmiettinen/cve-2022-21449-vuln-test

Java-based tester for CVE-2022-21449 ECDSA signature verification vulnerability. Checks JVM for the Psychic Signatures bug and reports vulnerable or…

cryptographyeducationpenetration-testing+2
24 years ago
CVE-2026-54519 preview

CVE-2026-54519

GitHubchaitanyagarware/cve-2026-54519

Public advisory landing page for CVE-2026-54519: missing ownership checks in ai-agent-automation memory APIs enabling cross-user memory read and…

ai-securityauthentication-authorizationcurated-resources+3
11 month ago
nextjs-cve-demo preview

nextjs-cve-demo

GitHublstudlo/nextjs-cve-demo

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

api-security-testingauthentication-authorizationeducation+3
21 year ago
CVE-2026-47101-PoC preview

CVE-2026-47101-PoC

GitHublearner202649/cve-2026-47101-poc

The code for personally reproducing the corresponding vulnerability

api-security-testingauthentication-authorizationeducation+7
3 months ago
CVE-2026-35030-PoC preview

CVE-2026-35030-PoC

GitHublearner202649/cve-2026-35030-poc

The code for personally reproducing the corresponding vulnerability

authenticationcryptographyeducation+5
3 months ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubjorrit-vm/cve-2026-33017

Educational lab demonstrating unauthenticated RCE in Langflow via CVE-2026-33017, with automated VM setup and a PoC exploit for reverse shell.

educationexploitationlabs-practice+6
14 months ago
nexus-os preview

nexus-os

GitLabnexaiceo/nexus-os

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

ai-securityauthentication-authorizationcloud-security+8
3 months ago
bola-CVE-2023-27524 preview

bola-CVE-2023-27524

GitHubrachidafaf/bola-cve-2023-27524

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

api-security-testingauthentication-authorizationeducation+3
5 months ago
GrafanaSCIMalform preview

GrafanaSCIMalform

GitHubi3r1h0n/grafanascimalform

Exploit and test stand for CVE-2025-41115

educationexploitationlabs-practice+3
9 months ago
SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit preview

SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit

GitHubsastraadiwiguna-purpleeliteteaming/sastra-adi-wiguna-cve-2026-21858-holistic-audit

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

curated-resourceseducationexploitation+4
7 months ago
CVE-2025-14857-MongoBleed preview

CVE-2025-14857-MongoBleed

GitHubermensonx/cve-2025-14857-mongobleed

Functional proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a pre-authentication heap memory disclosure vulnerability in MongoDB. Includes…

database-securityeducationexploitation+3
8 months ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubnehkark/cve-2025-62168

Proof-of-Concept (PoC) for CVE-2025-62168 👾

educationexploitationinformation-gathering+3
9 months ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

api-securityauthentication-authorizationcode-analysis+6
1 year ago
OnlyOffice-path-traversal preview

OnlyOffice-path-traversal

GitHubmihat2/onlyoffice-path-traversal

CVE-2023-46988: ONLYOFFICE Path Traversal Exploit

educationexploitationinformation-gathering+3
1 year ago
Previous1…111213Next